leapcat-ipo

Warn

Audited by Snyk on Mar 31, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly exposes a CLI for IPO market operations: listing IPO projects, estimating cost, and — critically — submitting and canceling IPO subscription orders via commands like "leapcat ipo subscribe --id --quantity " and "leapcat ipo cancel --subscription-id ". It requires trade-password, KYC, and balance/deposit actions, indicating it can execute real financial transactions (placing/canceling market-related orders). This is a specific financial execution capability, not a generic tool.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 31, 2026, 11:33 PM
Issues
1
Security Audit — snyk — leapcat-ipo